Canadian dental clinics operating in Alberta, British Columbia, or Quebec are not governed by PIPEDA alone. Each province has enacted its own substantially similar private-sector privacy legislation, and Alberta adds a layer most clinics overlook: dental professionals are named as custodians under the Health Information Act, not PIPA. Knowing which law applies, and what it demands, is the starting point for a compliant practice.
Why Provincial Privacy Laws Matter for Dental Clinics
PIPEDA, the federal Personal Information Protection and Electronic Documents Act, governs private-sector personal information across Canada. However, the Office of the Privacy Commissioner of Canada recognises that three provinces have enacted laws with protections substantially similar to PIPEDA: Alberta, British Columbia, and Quebec. For dental clinics that operate entirely within one of these provinces, the provincial law typically applies instead of PIPEDA for in-province data handling.
This distinction matters because the provincial laws carry their own consent requirements, breach notification rules, and penalty regimes. A clinic that assumes PIPEDA compliance automatically satisfies provincial law may be leaving real gaps, particularly if its province imposes stricter obligations.
For the authoritative list of substantially similar laws, see the Office of the Privacy Commissioner of Canada — Privacy laws in Canada.
British Columbia: PIPA and Your Dental Practice
British Columbia's Personal Information Protection Act (PIPA) governs every private-sector organisation that collects, uses, or discloses personal information in the province. The BC Office of the Information and Privacy Commissioner confirms that PIPA applies to healthcare providers in private practice, including dental clinics. The province also administers a separate E-Health (Personal Health Information Access and Protection of Privacy) Act, but that legislation targets prescribed public health custodians, not private dental offices.
Under BC PIPA, dental clinics must:
- Identify the purposes for collecting patient personal information before or at the time of collection
- Obtain meaningful consent, or have a valid legal reason to collect without consent
- Implement reasonable security safeguards proportionate to the sensitivity of the information
- Provide patients access to their own records on request and correct inaccuracies
- Appoint a privacy officer responsible for the clinic's PIPA compliance
A dental clinic that commits an offence under BC PIPA can face a fine of up to $100,000. Individuals (such as a practice owner who personally violates the Act) face fines up to $10,000. Affected patients may also pursue civil damages once a Commissioner order becomes final.
One nuance that catches many BC clinics off guard: BC PIPA contains no mandatory breach notification requirement. The original legislation is silent on proactive disclosure to the Commissioner or affected individuals. However, in practice, the OIPC strongly expects notification, and a failure to disclose can be used as evidence of inadequate safeguards. Clinics should treat the PIPEDA breach notification standard (report to the OPC, notify patients where there is a real risk of significant harm) as the effective floor for BC operations as well.
For the full list of legislation administered by the BC OIPC, see BC Office of the Information and Privacy Commissioner — Legislation.
Alberta: The Health Information Act for Dental Clinics
Alberta presents a more layered picture than BC. The province has its own Personal Information Protection Act (PIPA), which is also substantially similar to PIPEDA. However, Alberta dental professionals do not primarily fall under PIPA for patient health information. The province's Health Information Act (HIA) specifically names dentists, denturists, and dental hygienists as health custodians, meaning patient health records are governed by the HIA, not PIPA.
This distinction is significant. The HIA imposes its own framework for collecting, using, and disclosing health information, and it is administered by the Office of the Information and Privacy Commissioner of Alberta (OIPC Alberta). Dental clinics operating in Alberta must therefore maintain compliance with two separate regimes:
- Health Information Act (HIA): governs patient health records, clinical notes, treatment information, and any personal health information collected in the course of providing dental care
- PIPA (Alberta): covers non-health personal information your clinic may collect, such as employee records, commercial contact data, or billing information that is not part of a health record
As a health custodian under the HIA, a dental clinic must appoint a custodian representative, maintain records of all disclosures, and report any breach of health information "as soon as practicable" to three separate parties: affected individuals, the OIPC Alberta, and the Minister of Health. This triple-notification obligation is more demanding than the equivalent PIPEDA requirement and catches many clinics off guard. The HIA was also recently amended by Bill 11, which received Royal Assent in December 2025, so practices should confirm with the OIPC Alberta or qualified legal counsel that their current policies reflect the updated requirements.
Because Alberta PIPA is substantially similar to PIPEDA, any personal information your clinic handles that is not patient health information (employment data, marketing contact lists, supplier records) falls under PIPA. If that same information crosses provincial or national borders, PIPEDA also applies. Many Alberta clinics find it simplest to maintain PIPEDA-level standards across the board, then layer HIA requirements on top for clinical records. For the official HIA custodian obligations and resources, see Alberta.ca — Health Information Act.
Quebec: Law 25 and the Three-Phase Implementation
Quebec's privacy framework underwent its most significant modernisation in decades with the passage of Bill 64, commonly known as Law 25 — formally, An Act to modernise legislative provisions as regards the protection of personal information. The law amended the existing Act respecting the protection of personal information in the private sector (chapter P-39.1) and rolled out in three phases.
For Quebec dental clinics, the most consequential obligations relate to consent and incident management. Under the amended Act, clinics must:
- Designate a person responsible for the protection of personal information (the privacy officer role)
- Publish a clear, plain-language privacy policy on their website or in the practice
- Maintain a confidentiality incident register, recording any incident that involved a breach of data security, whether or not it presented a serious risk of harm
- Notify the Commission d'accès à l'information (CAI) and affected individuals when an incident presents a serious risk of harm to those individuals
- Implement privacy-by-default technological settings for any new system or platform handling patient personal information
Administrative monetary penalties under Law 25 can reach $10 million CAD or 2% of worldwide revenue, whichever is greater, for less serious violations. Penal sanctions for more serious contraventions can be higher still. These are among the most significant privacy penalties in Canada's private-sector framework.
The PIPEDA Cross-Border Rule Every Clinic Must Know
Even if your province has a substantially similar law, PIPEDA does not disappear entirely. The Office of the Privacy Commissioner of Canada is explicit: all businesses that handle personal information crossing provincial or national borders remain subject to PIPEDA, regardless of where they are based.
For dental clinics, this cross-border rule is triggered in practice by almost any cloud-based software platform. If your practice management system, patient communication tool, or appointment booking platform is hosted on servers in another province or country, the personal information flowing through that platform is subject to federal PIPEDA on top of your provincial law. This does not mean double the compliance work: because the provincial laws are substantially similar to PIPEDA, meeting one typically satisfies the other. However, PIPEDA's breach notification requirements (report to the OPC; notify affected individuals where there is a real risk of significant harm) do apply and cannot be assumed away by provincial compliance alone.
Province-by-Province Compliance Checklist
Use the checklist below as a starting point. It reflects the verified obligations discussed above. It is not a substitute for legal advice, and specific requirements may vary based on your clinic's structure and data flows.
- Appoint a privacy officer responsible for PIPA compliance
- Document the purpose of every category of personal information collected
- Obtain meaningful patient consent at or before the point of collection
- Implement security safeguards appropriate to the sensitivity of health records
- Create a process for patients to access and correct their information
- Although not legislatively required, maintain a breach response plan and treat PIPEDA notification standards as your floor
- Confirm your primary compliance obligation for patient health information is the Health Information Act (HIA), not PIPA
- Appoint a custodian representative under the HIA
- Maintain records of all disclosures of health information
- Report breaches of health information to the OIPC Alberta
- Apply PIPA to any non-health personal information (e.g. employee records, marketing data)
- Review your policies against the HIA as amended by Bill 11 (Royal Assent December 2025)
- Designate a person responsible for the protection of personal information
- Publish a clear, accessible privacy policy
- Maintain a confidentiality incident register for all security incidents
- Implement a process to notify the CAI and affected individuals of high-risk incidents
- Conduct privacy impact assessments before sharing patient data outside Quebec
- Ensure patient-facing systems use privacy-by-default settings
- Prepare for data portability requests (Phase 3, September 2024 onwards)
- Map every cloud service or software platform handling patient data and note where it is hosted
- Confirm whether PIPEDA breach notification requirements apply to each cross-border data flow
- Maintain a privacy policy that discloses cross-border transfers
- Ensure any third-party vendor handling patient data has signed a data processing agreement
Key Takeaways
- Three provinces have substantially similar laws to PIPEDA: Alberta, British Columbia, and Quebec. These laws generally apply instead of PIPEDA for in-province data handling, but PIPEDA reactivates for any cross-border data flows.
- Alberta dental clinics are primarily governed by the HIA: Dentists, denturists, and dental hygienists are named as health custodians under the Health Information Act. PIPA applies to non-health personal information only.
- BC PIPA applies directly to dental clinics in private practice. Organisational penalties reach $100,000. Breach notification is not mandated by the statute but treat PIPEDA standards as the effective floor.
- Quebec Law 25 is the most demanding of the three: Its three-phase rollout (2022 to 2024) introduced mandatory incident registers, privacy impact assessments, a designated privacy officer, and data portability rights. Administrative penalties reach $10 million or 2% of worldwide revenue.
- Cloud software nearly always triggers PIPEDA on top of provincial law. Map where your data is hosted and include cross-border transfer disclosures in your privacy policy.
DentRecall is an AI-powered dental recall and patient engagement platform built specifically for Canadian clinics. It automates SMS and email reminders and recall management from $99/month (billed annually), with online booking available on the Complete plan.
See how DentRecall works →